CVE-2026-40533
published 2026-09-18CVE-2026-40533: An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.29%
22.2th percentile
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synology | diskstation_manager | >= 7.2.1 < 7.2.1-69057-10 | 7.2.1-69057-10 |
| synology | diskstation_manager | >= 7.2.2 < 7.2.2-72806-7 | 7.2.2-72806-7 |
| synology | diskstation_manager | >= 7.3 < 7.3.2-86009-2 | 7.3.2-86009-2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794 / WID-SEC-2026-1125)
vuldb·2026-09-20·CVSS 5.3
CVE-2026-40533 [MEDIUM] Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API information disclosure (EUVD-2026-82794 / WID-SEC-2026-1125)
A vulnerability labeled as problematic has been found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This impacts an unknown function of the component Desktop API. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-40533. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
GHSA
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attack
ghsa_unreviewed·2026-09-18
CVE-2026-40533 [MEDIUM] CWE-202 An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attack
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published